Healthcare IT leaders walked into 2026 facing a familiar tension: the pressure to modernize faster than ever, against infrastructure and workflows that were never built for the pace being asked of them. Four forces are driving that tension right now: AI adoption in clinical workflows, interoperability, cybersecurity, and legacy modernization. And they’re deeply connected: solve one in isolation and the other three usually push back.
Here’s where each stands today:
AI in the clinical workflow, if the data can support it
Every health system conversation eventually turns to AI: ambient documentation, prior authorization automation, diagnostic support, and clinical decision tools. AI want is real. The readiness, less so. Across industries, roughly three-quarters of procurement and data leaders say their organization’s data isn’t actually AI-ready; it’s siloed, inconsistently labeled, or locked in legacy formats that models can’t reliably use. Healthcare feels this acutely, because clinical data lives across EHRs, imaging systems, lab platforms, and decades-old point solutions that were never designed to talk to each other.
The fix isn’t a model; it’s the data foundation underneath it: breaking down silos with data lakes and ETL pipelines, standardizing metadata and taxonomies, and building in governance and access controls from the start rather than bolting them on later. That groundwork is unglamorous, but it’s what determines whether an AI pilot actually scales past a proof of concept or stalls out because the underlying data can’t support it in production.
Interoperability is finally becoming operational, not aspirational
FHIR (Fast Healthcare Interoperability Resources) has become a standard everyone is actually building on. REST APIs, HTTP, and JSON-based exchanges are replacing batch file transfers and manual reconciliation that used to define how EHRs shared data, a shift that matters directly for AI and analytics initiatives, since neither works well with fragmented records.
This is where ClearBridge has spent a lot of its recent healthcare IT work. On one engagement, a government health agency brought in ClearBridge Mirth Integration Engineers to support a broader system modernization effort, building out health information exchanges using HL7, FHIR, REST services, and JSON-formatted data so disparate systems could exchange records in real time rather than through manual, point-to-point handoffs. The value wasn’t a single integration; it was building the connective tissue that let previously siloed stakeholders make faster, better-informed decisions as requirements kept shifting.
Cybersecurity: the threat isn’t slowing down, but the posture is maturing
The numbers are still sobering. Healthcare organizations reported roughly 789 large data breaches in 2025, affecting an estimated 138.5 million people, and hacking or other IT-related incidents accounted for more than 80% of those breaches. Early 2026 figures show breach counts running about 9.5% below the same period last year, a hopeful sign, though reporting delays make it too early to call a real trend reversal. Recent mega-breaches have made clear that a single point of failure in a connected health ecosystem can cascade across millions of patients almost instantly.
That’s the uncomfortable flip side of interoperability: every new API, every new data-sharing connection, is also a new attack surface. Health IT teams are responding by pairing integration work with information security architecture and governance rather than treating them as separate workstreams — building access controls, anonymization, and monitoring into the exchange layer itself, not as an afterthought.
Modernization: the infrastructure has to catch up
None of the above works on top of infrastructure that’s still running on aging, on-premises platforms. Health systems are steadily shifting EHR, clinical application, and revenue-cycle workloads to cloud environments and modern virtualization platforms, both to support real-time interoperability and to provide AI and analytics tools with the compute and access patterns they actually need. It’s rarely a clean rip-and-replace; it’s staged migrations, careful workflow and gap analysis, and change management to bring clinical and revenue-cycle staff along, since a modernization effort that ignores adoption tends to stall regardless of how sound the technical architecture is.
The throughline
AI, interoperability, cybersecurity, and modernization aren’t four separate initiatives competing for budget; they’re four faces of the same underlying challenge: building a health IT environment where data can move safely, quickly, and accurately to wherever it’s needed next. Organizations that treat them together, starting with clean, governed, interoperable data, are the ones best positioned to actually put AI and modern infrastructure to work, rather than being stuck in pilot mode.
ClearBridge has spent more than two decades working alongside health systems, government health agencies, and payers on exactly this kind of work, from FHIR-based health information exchanges to platform modernization under real-world regulatory and operational pressure. If your organization is navigating any one of these four forces, it’s worth having a conversation about the other three.
Email: [email protected]
According to IBM’s Cost of Data Breach Report, healthcare organizations incur the highest cost for data breaches of any industry, averaging $9.8 million per incident, more than 1.5 times the financial services industry’s $6.1 million. There is also a notable shift in attacker motivation, with espionage-driven attacks (actors after intellectual property and patient research data rather than a ransom payout) accounting for a much larger share of incidents than in prior years. Those actors are harder to catch because they aren’t trying to draw attention to themselves.
Healthcare IT leaders are heading into the back half of 2026 facing a collision of pressures: a looming overhaul of HIPAA’s Security Rule, breach costs that keep setting records, and a workforce gap that most organizations openly admit they can’t close on their own.
The compliance clock is ticking
The Office for Civil Rights is moving toward finalizing long-anticipated updates to the HIPAA Security Rule this year. The direction is clear: system-level, continuous risk analysis is becoming the baseline expectation, not a once-a-year checkbox exercise. Organizations that treat their last risk assessment as “done” are exactly where regulators are expected to look first.
That’s a meaningful operational shift for provider organizations that have historically run security reviews as an annual project rather than a standing discipline.
The cost of getting it wrong keeps climbing
Many government agencies canat’s where VMware Cloud Foundation comes in.
VMware Cloud Foundation Makes AI a Native Capability
VMware Cloud Foundation transforms the private cloud into an AI-ready platform by integrating virtualization, Kubernetes, networking, storage, security, automation, and lifecycle management into a unified operating environment.
Rather than treating AI as a separate project, VCF enables agencies to incorporate AI directly into their existing infrastructure.
With VMware Private AI technologies, agencies can bring advanced language models to their data. This approach allows organizations to:
- Keep sensitive information within secure environments
- Reduce the risks associated with moving data externally
- Improve AI performance by leveraging local infrastructure
- Accelerate deployment of generative AI applications
- Maintain governance and compliance requirements
The result is a secure foundation for adopting AI without compromising operational control.
Automation is Essential for Scaling AI
As agencies deploy more AI workloads, manual infrastructure management quickly becomes a bottleneck. Platform engineering and automation are critical to delivering AI services consistently and securely.
Using technologies such as:
- VMware Aria Automation
- Infrastructure as Code (IaC)
- Terraform
- GitOps
- Kubernetes
- CI/CD pipelines
organizations can automate infrastructure provisioning, policy enforcement, application deployment, and lifecycle management. Automation enables IT teams to spend less time managing infrastructure and more time delivering mission capabilities.
Security Must Be Embedded From the Start
Government AI initiatives require security at every layer of the infrastructure stack. VMware Cloud Foundation supports this through:
- Integrated Zero Trust networking
- Microsegmentation with VMware NSX
- Identity-based access controls
- Infrastructure lifecycle management
- Continuous monitoring
- Policy-driven automation
- Built-in compliance capabilities
Rather than adding security after deployment, agencies can build secure-by-design AI platforms from day one.
Observability Keeps AI Operations Running
AI environments generate significant infrastructure demands. Maintaining visibility across compute, storage, networking, Kubernetes clusters, and applications is essential for operational success. Modern observability platforms provide insights into:
- Infrastructure health
- Resource utilization
- AI workload performance
- Capacity planning
- Security events
- System availability
With proactive monitoring and analytics, agencies can identify issues before they affect mission-critical operations.
How ClearBridge Helps Government Organizations Prepare for AI
Successfully implementing an AI-ready private cloud requires expertise across infrastructure, automation, security, networking, and cloud operations. ClearBridge helps federal agencies modernize their environments with consultants experienced in:
- VMware Cloud Foundation design and implementation
- Private cloud modernization
- Kubernetes platform engineering
- VMware NSX and Zero Trust architectures
- VMware Aria Automation
- Infrastructure as Code using Terraform
- Platform engineering and GitOps
- AI-ready infrastructure planning
- Observability and operations
- Secure cloud migrations
Whether agencies are modernizing existing VMware environments, preparing for AI initiatives, or building scalable private cloud platforms, ClearBridge provides the technical expertise needed to accelerate deployment while reducing implementation risk.
Preparing for the Next Phase of Government AI
America’s AI Action Plan signals a clear direction: AI will become an increasingly important part of government operations. The agencies that succeed won’t simply deploy AI applications; they’ll build secure, scalable platforms that support AI for years to come. A private cloud powered by VMware Cloud Foundation provides a practical path forward, enabling agencies to harness advanced AI capabilities while maintaining security, governance, and operational control of their missions demand.
Partner with ClearBridge
As a VMware by Broadcom premier strategic partner with deep expertise in VMware Cloud Foundation, private cloud modernization, automation, and platform engineering, ClearBridge helps government organizations build the AI-ready infrastructure needed to support tomorrow’s mission-critical workloads.
Ready to prepare your infrastructure for the next generation of AI? Contact ClearBridge to learn how our VMware experts can help you build a secure, scalable, AI-ready private cloud.
Recent Comments